# Pocodot security.txt — coordinated disclosure & researcher contact # Spec: RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116) # # Have you found a security issue in Pocodot? We want to hear from you. # Please email the address below — we reply within one business day. Contact: mailto:security@pocodot.ai Contact: https://pocodot.ai/contact-sales Expires: 2027-05-13T00:00:00.000Z Encryption: https://pocodot.ai/security/deletion-key Preferred-Languages: en Canonical: https://pocodot.ai/.well-known/security.txt Policy: https://pocodot.ai/security Acknowledgments: https://pocodot.ai/security Hiring: https://pocodot.ai/careers # Scope # In scope: *.pocodot.ai # Out of scope: # - Denial-of-service attacks (please don't) # - Social-engineering of Pocodot teammates # - Physical attacks on our offices or infrastructure # - Findings against third-party services we use (please report directly to them) # # Safe-harbour # We will not pursue legal action against researchers who follow coordinated # disclosure: act in good faith, do not access or modify other customers' # data, do not exfiltrate data beyond what is needed to demonstrate the issue, # and give us reasonable time to respond before public disclosure. # # Recognition # With your permission, we will credit you in our release notes when the fix # ships.